Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises shell-capable operations such as cloning repositories, editing shell startup files, and managing backups/updates, but does not declare any permissions. This creates a transparency and trust problem: users and policy engines cannot accurately assess that the skill can execute system commands and modify the local environment.
